GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

VND-004 Cloud Service Provider Security Management

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A documented process governs the selection, security assessment, configuration, monitoring, and exit from cloud service providers (IaaS, PaaS, SaaS). Shared responsibility boundaries are documented. CSP security configurations are reviewed against organisational baseline standards. Exit provisions and data portability requirements are addressed contractually.

Rationale

Cloud providers underpin most product architectures but shared responsibility confusion is a leading cause of cloud misconfiguration breaches. Explicit CSP management is required where cloud services are the primary infrastructure.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore

The control through which the deployer evidences every hosted-tier control inherited from a cloud provider.

GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore

The control through which the deployer evidences every hosted-tier control inherited from a cloud provider.

DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (11)

IPY-04Data Portability Contractual Obligationspartial
STA-11Primary Service and Contractual Agreementpartial
IPY-04Data Portability Contractual Obligationspartial
STA-11Primary Service and Contractual Agreementpartial
5.23Information security for use of cloud servicesfull
NIS2-CIR-5.1Supply Chain Security Policyinformative
AU-16Cross-organizational Audit Logginginformative
CA-2(3)Control Assessments | Leveraging Results from External Organizationsinformative
SA-9External System Servicesinformative
SR-2Supply Chain Risk Management Planpartial
GOVERN 6.1Third-Party AI Risk Policiespartial

Evidence (2)

policydocumentmanual

Cloud service provider management policy documenting selection criteria, shared responsibility documentation requirements, configuration baseline standards, and exit procedures.

Example: Cloud Security Policy (Confluence), approved by CISO, defining: CSP due diligence requirements, mandatory shared responsibility matrix, minimum security configuration baselines (e.g. CIS Benchmarks), contractual data portability requirements, and exit planning obligations

Test: Request the cloud security or provider management policy. Verify: (1) it requires a shared responsibility matrix for each provider in use, (2) it references a published security configuration benchmark for the providers in use, (3) it requires contractual data portability terms, (4) it requires exit planning, (5) it carries an approval within the defined interval.

recorddocumentmanual

Completed shared responsibility matrix for the primary cloud provider documenting which controls are CSP-managed, organisation-managed, or shared.

Example: Shared Responsibility Matrix (Confluence / spreadsheet) for the primary CSP (e.g. AWS, GCP, Azure), mapping each control domain to CSP / Organisation / Shared responsibility, with references to CSP documentation confirming CSP-owned controls and internal evidence for organisation-owned controls

Test: Request the shared responsibility matrix for the primary CSP. Verify: (1) covers all major control domains (physical security, network, platform, identity, data, application), (2) organisation-owned controls have corresponding evidence artefacts referenced, (3) matrix has been reviewed within 12 months, (4) reviewed and approved by the CISO or equivalent.

Questions (2)

boolean

Is there a documented process governing the selection, security assessment, configuration, monitoring and exit of cloud service providers?

The process should include security baseline configuration standards (e.g. CIS Benchmarks), documented shared responsibility boundaries, and contractual data portability and exit provisions. Misconfiguration of cloud services is a leading cause of security incidents.

multi

Which elements of cloud service provider security management are formally documented in your organisation?

Shared responsibility matrix for the primary CSPBaseline security configuration standard referencing the CSP (e.g. CIS Benchmarks for AWS, GCP, Azure)Regular review of CSP configurations against the baselineContractual data portability and exit provisionsCSP exit planning and data migration procedureNone of the above

A shared responsibility matrix and documented configuration baseline are the minimum expected artefacts. Exit planning is critical to ensure data can be recovered or migrated if the CSP relationship ends.